CVE-2025-66035General

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201CWE-359

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • BREACHSPIDER@breachspider
    General

    [CVE Analysis] CVE-2025-66035: Memory Corruption Flaws in Siemens SINEC OS Threaten RUGGEDCOM RST2428P Substation Switches https://breachspider.com/intel/2026-07-09-cve-2025-66035-memory-corruption-flaws-in-siemens-sinec-os-t #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The text announces a memory corruption vulnerability (CVE‑2025‑66035) affecting Siemens SINEC OS on RUGGEDCOM switches, but provides no exploit or mitigation details.

    0000039
    2.3K followersView on X

Explore more